Cross-Site Request Forgery Vulnerability in Zawgyi Embed Plugin for WordPress
CVE-2026-7616
4.3MEDIUM
What is CVE-2026-7616?
The Zawgyi Embed plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) attack due to inadequate nonce validation in the zawgyi_adminpage function. This vulnerability allows unauthorized attackers to manipulate the plugin’s zawgyi_forceCSS setting through forged POST requests. By tricking an administrator into executing a malicious action — such as clicking a deceptive link — an attacker can exploit this flaw, leading to unauthorized changes in the plugin settings.
Affected Version(s)
Zawgyi Embed 0 <= 2.1.1